21st Century Oncology operates 179 cancer treatment centers across the U.S. and Latin America. According to court documents, the center failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to its electronic protected health information. It had also failed to implement certain security measures and properly review its security systems.
The documents also allege 21st Century Oncology disclosed PHI to third party vendors, despite obtaining a written business associate agreement outlining satisfactory assurances.
This marks another legal hurdle for the company, which also agreed to pay the federal government $26 million to resolve false claims allegations and a self-disclosure that it submitted false attestations regarding the use of EHR software. That settlement also resolves allegations that 21st Century Oncology violated the False Claims Act and Stark Law by submitting claims to government payers for services performed by physicians with whom it had improper financial relationships.
In addition to the monetary settlement, 21st Century Oncology entered into a five-year corporate integrity agreement with HHS’ Office of Inspector General. The company filed for Chapter 11 bankruptcy in May.
More articles on cybersecurity:
Medical identity theft affects different states at different rates: 3 things to know
Mercy Health joins Avia innovation network
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.